What probably matters to youSection of the release
What
Before Claude runs a shell command, Claude Code checks whether it needs your permission. That check now looks inside inline shell scripts, meaning code passed as text to bash -c, sh -c or zsh -c, and judges any rm in them.
An rm whose target comes from a variable or from another command's output, so it is only known when the script runs, now triggers a prompt: Dangerous rm operation in a shell -c script.
A script that cannot be checked, or a permission-rule deny found inside the script, also leads to a prompt instead of automatic approval.
The prompt counts as a dangerous-removal safety check (dangerousRemovalsafetyCheck), so your permission rules cannot allow it automatically.
Nested shell code is judged recursively, with a shared depth and budget limit. The result of this new pass is inlineShellScript.
A new heredoc_redirect path re-reads commands with plain unquoted heredocs (blocks of text fed into a command) so they can be auto-allowed when sandboxing is on and auto-allow for sandboxed commands is enabled. It is behind tengu_amber_larch. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.
Why
Before this change, an rm wrapped inside a bash -c script could get past the dangerous-removal check that a plain rm would hit. Expect new prompts for scripted commands such as rm -rf $VAR, and know that allow rules will not silence them. Set the environment variable if you need the old behaviour.
Read from
Feature flag
tengu_amber_larchOn for this account, and not off by default
The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.
This account: on · anonymous baseline: on · compiled default in v2.1.288: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.